Difficult login page examples needed!

68 views
Skip to first unread message

Simon Bennetts

unread,
Jan 14, 2025, 7:25:14 AM1/14/25
to ZAP User Group
ZAP Browser Based Authentication makes authenticating to modern web apps so much easier, when it works.

However we are aware that is does not work in all cases, so we have plans to make it much better.

For that we need your help!

Please let us know of example login pages that it doesnt work with. You can test them using the Authentication Tester.
For now we just want to know about login pages where it cannot successfully identify and fill in the username and password fields.

Ideally we'd like a public URL - you can post them to this conversation or email them to us via zaprox...@googlegroups.com
Failing that the relevant HTML for the input fields in the DOM might give us the info we need.
We do not need any credentials, we just need to be able to see whether ZAP can fill test credentials in and submit the form.

Many thanks,

Simon

Sachin Verlekar

unread,
Jan 14, 2025, 7:45:30 AM1/14/25
to zaprox...@googlegroups.com
Hi Simon,

I would suggest trying with OAuth platform login examples such as Authentik (Which is open source and free)vand Auth0 (Not sure whether free version is available or not). Their authentication flow is very complex has 2FA and it has shadow DOMS. So for this, we had to code manually using selenium and put xpaths of all those text fields during the chrome browser automation mode. 

Thanks & Regards,
Sachin 

--
ZAP by Checkmarx: https://www.zaproxy.org/
---
You received this message because you are subscribed to the Google Groups "ZAP User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-user...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/zaproxy-users/4d9f9a42-386a-4f76-9a19-66ac08347438n%40googlegroups.com.

Sachin Verlekar

unread,
Jan 14, 2025, 7:46:38 AM1/14/25
to zaprox...@googlegroups.com

Simon Bennetts

unread,
Jan 14, 2025, 9:57:23 AM1/14/25
to ZAP User Group
Thanks Sachin - they look like great examples!

András Lánczky

unread,
Feb 18, 2026, 6:21:32 AM (3 days ago) Feb 18
to ZAP User Group
Hi Simon, is there any follow up on this thread? Thanks.

Simon Bennetts

unread,
Feb 20, 2026, 12:39:13 PM (yesterday) Feb 20
to ZAP User Group
We've not had a chance to test those specific sites / techs.
But we have made _lots_ of improvements to the ZAP auth handling over the last year.
If anyone knows of any public sites that ZAP cannot handle well then just let us know.

Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages